Announcement

Collapse
No announcement yet.

PCI DSS 4.0 External Compliance Scan

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    V18.2.2
    Concerning Jonathan's Post #118 regarding authorisation and integrity of js files in the site folder using the command prompt, I am finding that the CertUtil: -hashfile command FAILS for "sdwidget.min.js".

    All other js files in my site folder result in CertUtil: -hashfile command completed successfully.

    Does anyone else get the same result running the command prompt for "sdwidget.min.js"?
    Martin

    Comment


      Originally posted by Mantra View Post
      I have had a brief look at what the Security Metrics Shop Cart Monitor can do and find that it addresses some of the requirements I was considering separately, so it is certainly of interest for me saving time and effort to have in place before 31 March and may be worth considering by others.
      Have any others implemented Security Metrics Shop Cart Monitor?

      Martin

      Comment


        Well a year of failing scans now, I have sent the latest report to Sellerdeck (my host and I am a 365 customer)..
        I hope this can be resolved.

        Ed
        https://www.harrisontelescopes.co.uk/

        Ed Harrison - Menmuir Scotland

        Comment


          We've been using Sellerdeck's own for compliance thing via worldline site :
          https://clearaccept.worldline-pcipor...r/login/portal

          No problems so far, I don't know if worldline scans are not so strict?

          Our host = hostit << I remember they did help with various settings to getting it all compliant
          (I'm glad we left 365... they weren't keen on keeping our business way back then, and I hated every aspect of leaving them at the time)

          What happens when it fails for such a long time?
          - do you get fined / pay extra charges like a non-compliance fee?

          Comment


            I've tried getting Sellerdeck to resolve this for a year they just reply with it may take some time...yes!
            So far I'm passing PCI on all but the scans, Security metrics say it isn't difficult for the host (Sellerdeck) to resolve as it's mainly updates needed.
            Frustrating but moving host or platform isn't fun either...
            https://www.harrisontelescopes.co.uk/

            Ed Harrison - Menmuir Scotland

            Comment


              Unfortunately no reply two days later from the open support ticket...
              https://www.harrisontelescopes.co.uk/

              Ed Harrison - Menmuir Scotland

              Comment


                I'm surprised Sellerdeck Hosting still isn't working 100% with compliance.

                Their "in-house" products are supposed to have quick support fixes, they don't seem to be:
                - I'm still waiting on the fix to the csv export on their Sellerdeck Pay by ClearAccept (almost a year)... that was a sunset from Sellerdeck Payments by NMI / CreditCall, and supposed to be "in-house"=quick fixes... nope.

                Here's a link I bookmarked when we had 365
                https://search.dnslytics.com/search?...&q=81.29.88.81

                Your site's IP = 81.29.88.131
                https://search.dnslytics.com/search?...q=81.29.88.131

                Cannot tell if Sellerdeck themselves are managing the servers directly, or they contact the hosting company support to fix.

                Comment


                  They have replied now, unfortunately not looking like they intend their hosting to be compliant any time soon...should they really be promoting a platform with non compliant hosting for ecommerce..
                  365 customers like myself are paying thousands a year for this.
                  https://www.harrisontelescopes.co.uk/

                  Ed Harrison - Menmuir Scotland

                  Comment


                    Ed, I fear Sellerdeck is in a downward spiral, let’s face it they haven’t reassured us after the topic a few months back.

                    For me the choices are suffer the decline, or move software before we are suddenly forced to. I am currently moving 1 of our 3 sites to a different package. The other 2 will remain on Sellerdeck for the time being.

                    The other software package I am using impresses me every day, and saddens me that I didn’t look into alternatives sooner.

                    And support is 24/ 7 and generally in minutes.
                    Regards

                    Jason

                    Titan Jewellery
                    Titan Blog

                    Comment


                      Jason, is it woo or shopi?

                      Ed
                      https://www.harrisontelescopes.co.uk/

                      Ed Harrison - Menmuir Scotland

                      Comment


                        Ed - Have you had a read of this page ?

                        https://portal.sellerdeck.co.uk/sell...ss-compliance/
                        www.devotedly-discus.co.uk

                        Comment


                          Wow that's incredible given my experience with them over this!
                          https://www.harrisontelescopes.co.uk/

                          Ed Harrison - Menmuir Scotland

                          Comment


                            Originally posted by EdHarrison View Post
                            Jason, is it woo or shopi?

                            Ed
                            I looked at both and shop seemed too restricted for me.

                            I have been woo’d with the package I’m on, page sights score of 95 for speed etc. I’m not doing a simple conversion though, I’m rebuilding from the ground up, so still a few months away from going live. I opted after a lot of research for a host called Kinsta which I have been impressed with as well.

                            If you want any info, drop me an email, be happy to help.
                            Regards

                            Jason

                            Titan Jewellery
                            Titan Blog

                            Comment

                            Working...
                            X